Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Enabled static ARP - now I'm locked out of pfSense, help!

    Scheduled Pinned Locked Moved DHCP and DNS
    22 Posts 3 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kejianshi
      last edited by

      OK - Lets try one step at time.  OK?

      I don't know if this will work with your problem.

      Can you access the pfsense console menu?

      If so, let it boot up, go to command line then enter:

      pfctl -d

      Now check to see if you have access to web gui.

      1 Reply Last reply Reply Quote 0
      • J
        JohnnyBeGood
        last edited by

        Ok, I have access to the box shell.
        Pfctl -d gives me "Pfctl: pf not enabled"

        I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          Can you access the web configurator?

          1 Reply Last reply Reply Quote 0
          • J
            JohnnyBeGood
            last edited by

            @kejianshi:

            Can you access the web configurator?

            No, that's the issue. As soon as I hit save I was cut off from everything. Can't even ping 192.168.1.1

            I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              Reboot.  Go back to the console and restore recent configuration.

              Its option 15.

              See if you can select the one before you made the ARP change.

              Apply it.  After its all done, reboot and try to get to web gui.

              1 Reply Last reply Reply Quote 0
              • J
                JohnnyBeGood
                last edited by

                @kejianshi:

                Reboot.  Go back to the console and restore recent configuration.

                Its option 15.

                See if you can select the one before you made the ARP change.

                Apply it.  After its all done, reboot and try to get to web gui.

                Thank you!!!! I'm back online :D
                Restoring "05" fixed my issue.
                Could this be a possible bug?

                Capture5.JPG
                Capture5.JPG_thumb

                I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  Not sure if its a bug.  Its not an option I use.  I just know how to undo it.  :P

                  Glad you are up and running.  I'd save the config from time to time.  I name mine after the major changes made to them + a date.

                  1 Reply Last reply Reply Quote 0
                  • J
                    JohnnyBeGood
                    last edited by

                    I hope Jim or someone else will chime in. If its not a bug then at least explain the purpose of this option so that others don't run into same issue. I'm willing to supply more info if needed.

                    20130922_234252.jpg_thumb
                    20130922_234252.jpg

                    I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      How many computers/devices do you have listed at the bottom of that page?
                      Was your current computer in the list?
                      Is anything at all in the list?
                      Do you have static IP entries listed there?

                      1 Reply Last reply Reply Quote 0
                      • K
                        kejianshi
                        last edited by

                        All your images are on the board.  No need for the drop-box item.  We see the images even if you can't.

                        So, did you have your computers listed on that page at bottom?

                        1 Reply Last reply Reply Quote 0
                        • J
                          JohnnyBeGood
                          last edited by

                          @kejianshi:

                          All your images are on the board.  No need for the drop-box item.  We see the images even if you can't.

                          So, did you have your computers listed on that page at bottom?

                          Just one.

                          Capture7.JPG
                          Capture7.JPG_thumb

                          I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi
                            last edited by

                            OK - The the static ARP did what it was supposed to do.  Only the xbox would have been allowed access after you clicked that box.
                            If you want more computers, you need to make sure they have a static entry at the bottom of that page and then click the button.

                            Then you should, in theory, not get locked out.

                            1 Reply Last reply Reply Quote 0
                            • K
                              kejianshi
                              last edited by

                              I have about 10 or so entries on the LAN - but I think static ARP would be inconvenient for me.  I add and subtract devices often.

                              1 Reply Last reply Reply Quote 0
                              • J
                                JohnnyBeGood
                                last edited by

                                @kejianshi:

                                OK - The the static ARP did what it was supposed to do.  Only the xbox would have been allowed access after you clicked that box.
                                If you want more computers, you need to make sure they have a static entry at the bottom of that page and then click the button.

                                Then you should, in theory, not get locked out.

                                Ok, when I read it again it does make sense. All I wanted to do is create a static ARP so that particular MACs always get same IP.
                                I've managed to do that in 2.0.1 http://forum.pfsense.org/index.php/topic,40451.msg211283.html#msg211283
                                Would you know how I can achive saem resault instead of using assign IP outside DHCP server range?
                                Before after setting above ARP mod I was able to set static IP on each computer and WOL would always work.

                                I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                                1 Reply Last reply Reply Quote 0
                                • K
                                  kejianshi
                                  last edited by

                                  The best way to do it is to go to status > DHCP leases find the computers you want to give permanent entries to.

                                  Press the + button out to the right.

                                  It will take take you to the place to define the Name, IP and DNS name to give according to the MAC.

                                  THEN it will appear in the bottom of that list.

                                  1 Reply Last reply Reply Quote 0
                                  • J
                                    JohnnyBeGood
                                    last edited by

                                    @kejianshi:

                                    The best way to do it is to go to status > DHCP leases find the computers you want to give permanent entries to.

                                    Press the + button out to the right.

                                    It will take take you to the place to define the Name, IP and DNS name to give according to the MAC.

                                    THEN it will appear in the bottom of that list.

                                    That way all of my added computers will get IPs out of DHCP server range (my current range is 192.168.1.100-192.168.1.120)
                                    With that mod I was able to stay inside DHCP range and still have static ARP.
                                    1st computer 192.168.1.100
                                    2nd computer 192.168.1.101
                                    etc.
                                    It was easy to remember each comp. IP.

                                    I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                                    1 Reply Last reply Reply Quote 0
                                    • K
                                      kejianshi
                                      last edited by

                                      Thats a weird personal preference ;)

                                      Well - Looks like you are all good.  Enjoy.

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        JohnnyBeGood
                                        last edited by

                                        Thanks for your help! I'll try to make it like it was before  ;)

                                        I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          protonelge
                                          last edited by

                                          How were you able to access the console if address 192.168.1.1 did not ping? I'm in the same situation and since I just got the box I will just factory reset it, but it might be helpful for other folks to know.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.